If you have an outdoor Ethernet port—in my case with a WiFi AP connected—how can you go about protecting your network from somebody jacking in?

Is there a way to bind that port to only an approved device? I figured a firewall rule to only allow traffic to and from the WiFi AP IP address, but would that also prevent traffic from reaching any wireless clients connected to the AP?

Edit: For more context, my router is a Ubiquiti UDM and the AP is also Unifi AP

  • @friend_of_satan
    link
    English
    114 months ago

    https://en.m.wikipedia.org/wiki/IEEE_802.1X

    The standard directly addresses an attack technique called Hardware Addition where an attacker posing as a guest, customer or staff smuggles a hacking device into the building that they then plug into the network giving them full access.

    • @[email protected]
      link
      fedilink
      English
      24 months ago

      Yup, I had to implement this for a customer once, and while it was a paid, it does require authentication before getting access to the network.